Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2025-54723 Deserialization of Untrusted Data vulnerability in BoldThemes DentiCare denticare allows Object Injection.This issue affects DentiCare: from n/a thro… Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.0 CVE-2025-33210 NVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to code execution. Isaac Lab 2.3.0+ Fix from $2,3002025-12-16 HIGH 7.8 CVE-2025-33212 NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to exploit improper control mechanisms if a user loads a… Nemo 2.5.3+ Fix from $1,9502025-12-16 HIGH 7.8 CVE-2025-33226 NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a code injection. A successful… Nemo 2.5.3+ Fix from $1,9502025-12-16 HIGH 7.8 CVE-2025-67747 Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 are missing `marshal` and `types` from the block list of unsafe… Fickling 0.1.6+ Fix from $1,9502025-12-16 HIGH 7.8 CVE-2025-67748 Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of uns… Fickling 0.1.6+ Fix from $1,9502025-12-16 HIGH 8.8 CVE-2025-9121 Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted… Mitigation only Fix from $1,9502025-12-15 CRITICAL 9.8 CVE-2025-65213 MooreThreads torch_musa through all versions contains an unsafe deserialization vulnerability in torch_musa.utils.compare_tool. The compare_for_singl… Torch Musa Mitigation only Fix from $2,3002025-12-15 MEDIUM 5.0 CVE-2025-14606 A security vulnerability has been detected in tiny-rdm Tiny RDM up to 1.2.5. Affected by this vulnerability is the function pickle.loads of the file … Mitigation only Fix from $1,6002025-12-13 HIGH 8.8 CVE-2025-14476 The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1… Mitigation only Fix from $1,9502025-12-13 HIGH 8.8 CVE-2025-26866 A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix en… Hugegraph 1.7.0+ Fix from $1,9502025-12-12 HIGH 8.1 CVE-2025-14044 The Visitor Logic Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.3 via deserialization of … Mitigation only Fix from $1,9502025-12-12 HIGH 7.5 CVE-2025-67779EPSS 20% It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a sp… React 14.2.35 / 15.0.7+ Fix from $1,9502025-12-12 HIGH 7.5 CVE-2025-55184EPSS 67% A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.… React 14.2.35 / 15.0.7+ Fix from $1,9502025-12-11 CRITICAL 9.8 CVE-2025-34394 Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insufficiently p… Rmm 2025.1.1+ Fix from $2,3002025-12-10 HIGH 8.7 CVE-2025-9571 A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifacts to a Data Fusion instance… Mitigation only Fix from $1,9502025-12-10 HIGH 8.4 CVE-2025-61810EPSS 9% ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbit… Coldfusion Mitigation only Fix from $1,9502025-12-10 HIGH 8.8 CVE-2025-66214 Ladybug adds message-based debugging, unit, system, and regression testing to Java applications. Versions prior to 3.0-20251107.114628 contain the AP… Ladybug 3.0-20251107.114628+ Fix from $1,9502025-12-09 CRITICAL 9.3 CVE-2025-34414 Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 … Mitigation only Fix from $2,3002025-12-09 HIGH 8.8 CVE-2025-33213 NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A succe… Mitigation only Fix from $1,9502025-12-09 HIGH 8.8 CVE-2025-33214 NVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, where a user could cause a deserialization issue. A successful exploit… Mitigation only Fix from $1,9502025-12-09 MEDIUM 6.6 CVE-2025-67535 Deserialization of Untrusted Data vulnerability in Flipper Code - WordPress Development Company WP Maps wp-google-map-plugin allows Object Injection.… Mitigation only Fix from $1,6002025-12-09 CRITICAL 9.8 CVE-2025-66631 CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow t… Csla .net 6.0.0+ Fix from $2,3002025-12-09 CRITICAL 9.1 CVE-2025-42928EPSS 9% Under certain conditions, a high privileged user could exploit a deserialization vulnerability in SAP jConnect to launch remote code execution. The s… Mitigation only Fix from $2,3002025-12-09 HIGH 8.8 CVE-2025-63721 HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component, allowing attackers with normal user privileges to hit the /rule/add API and thereby… Hummerrisk after 1.5.0 Fix from $1,9502025-12-08 CRITICAL 9.3 CVE-2025-66571 UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where the profile_id POST parameter… No fix yet Fix from $2,3002025-12-04 CRITICAL 10.0 CVE-2025-55182 KEVEPSS 100% A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the … React 15.0.5 / 15.1.9+ Fix from $2,3002025-12-03 HIGH 7.8 CVE-2025-41700 An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CO… Codesys 3.5.21.40+ Fix from $1,9502025-12-01 MEDIUM 6.3 CVE-2025-9191 The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via deserialization of untrusted inp… Mitigation only Fix from $1,6002025-11-26 HIGH 8.8 CVE-2025-62703 Fugue is a unified interface for distributed computing that lets users execute Python, Pandas, and SQL code on Spark, Dask, and Ray with minimal rewr… Fugue after 0.9.1 Fix from $1,9502025-11-25